CVE-2021-24507
CRITICALAstra Pro Addon < 3.5.2 - SQL Injection via astra_pagination_infinite and astra_shop_pagination_infinite AJAX Actions
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-24507. PoCs published by RandomRobbieBF.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-24507, an unauthenticated SQL injection vulnerability in Astra Pro Addon versions before 3.5.2. The exploit automates the extraction of a nonce and tests for both error-based and boolean-based SQL injection.
Description
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues
Exploits (1)
This repository contains a functional exploit for CVE-2021-24507, an unauthenticated SQL injection vulnerability in Astra Pro Addon versions before 3.5.2. The exploit automates the extraction of a nonce and tests for both error-based and boolean-based SQL injection.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H